Skip to content
Vulnerabilities

Security in the AI Era Starts with First Principles 

Written By Alfredo Hickman, CISO, Kai  Artificial intelligence is evolving so rapidly that keeping up can feel daunting. New models, capabilities, and attack vectors seem to emerge almost daily, pressuring CISOs to constantly adjust their security strategies. Security leaders have recognized that sh...

· Jul 27, 2026 · 7 min read · 👁 0 views
Security in the AI Era Starts with First Principles 

Written By Alfredo Hickman, CISO, Kai 

Artificial intelligence is evolving so rapidly that keeping up can feel daunting. New models, capabilities, and attack vectors seem to emerge almost daily, pressuring CISOs to constantly adjust their security strategies.

Security leaders have recognized that shift.  

In Kai’s recent survey of 500 CISOs, nearly nine in ten (89%) said they are prepared for AI-driven attacks, yet only 28% described themselves as very prepared.

At the same time, 63% believe attackers currently have the advantage because of AI, and 65% say the time between vulnerability disclosure and exploitation has increased.

Those findings reveal an important distinction: preparedness is not the same as readiness. Understanding the threat is one thing. Operating at the speed required to respond is another. 

However, even the engineers building frontier AI systems will acknowledge a simple truth: no one knows exactly what AI will look like in 12, 24, or 36 months.

That uncertainty makes it risky to build security programs around today’s technologies alone. We believe there is a better approach: start from first principles.

While AI will continue to transform how organizations operate, the fundamentals of good security remain consistent and, in many cases, have become even more important. The technology will evolve, but the basic principles that make organizations secure will not. 

Resilience Is the Foundation of Modern Security 

The first principle is resilience. Every security leader knows that preventing each and every cyberattack is nearly impossible. AI doesn’t change that reality, rather, it changes the economics of cyberattacks.  

We’re already seeing AI lower the barrier to entry, accelerate the speed of attacks, and allow adversaries to operate at greater scale.

The attacks themselves are not novel, they are just becoming cheaper, faster, and easier to execute.

That means organizations should expect more frequent disruption, not fewer attempts.

Security leaders must architect organizations that can detect, contain, and recover quickly. Resilience then must become a strategic design principle that enables organizations to embrace innovation without sacrificing operational continuity. 

The challenge is that many organizations are still trying to respond to machine-speed attacks with human-speed operations.

Kai’s research found that 65% of organizations say their vulnerability management processes are still at least half manual.

60% require more than one week to remediate critical vulnerabilities, while nearly half report that at least one-quarter of known vulnerabilities remain unresolved for more than 30 days. 

Every additional day between identifying and remediating a vulnerability creates another opportunity for attackers.

In an environment where AI is compressing the time between disclosure and exploitation, resilience isn’t just about recovering from incidents. 

It’s about reducing the time between detection, decision, and action so defenders can keep pace with increasingly automated threats. 

Identity and Zero Trust Become Even More Critical 

The second principle is identity. Identity has long been the cornerstone of modern security, but AI raises the stakes considerably.

Organizations are now managing far more than just human users – they’re managing models, applications, APIs, and autonomous agents that each require varying levels of access to sensitive systems and data.

As AI becomes embedded across the enterprise, identity becomes the control plane that determines who or what is allowed to act.  

That makes Zero Trust architecture, continuous verification, and least-privilege access more important than ever. But technology alone isn’t enough. Organizations also need to rethink governance.

As AI becomes capable of taking increasingly sophisticated actions, organizations need clear policies defining which systems can operate autonomously, under what conditions, and with what oversight.

Kai’s study found that governance and compliance concerns remain one of the largest barriers to broader automation adoption. That’s understandable.

Before organizations allow AI to take action, they need confidence that those actions will be transparent, explainable, and aligned with existing security policies. 

Organizations must invest in educating their workforce, retooling security programs for an AI-native environment, and engaging business leaders and boards so governance evolves alongside technology.

Strong identity isn’t just a technical control; it’s an organizational discipline. 

AI Requires Rethinking Trust, Not Abandoning It 

The third principle is managing trust with greater precision. Traditional software generally executes predefined instructions, but agentic AI increasingly makes decisions and initiates actions on behalf of users and organizations.

This shift requires us to be much more deliberate about where trust is granted and how it is constrained within an organization.  

The survey suggests this is where many organizations are today. More than half of CISOs (52%) identified a lack of trust in automated decisions as the single biggest barrier preventing broader automation adoption.

Governance concerns followed closely behind, while skills shortages and integration complexity also ranked among the leading challenges.

The priority has become helping security leaders develop enough confidence to allow AI to take meaningful action.  

Most organizations are already comfortable using AI for lower-risk activities like asset discovery, inventory management, and vulnerability prioritization.

The hesitation begins when systems move beyond recommending actions to executing them autonomously. I believe that’s the right conversation to have.

Security leaders should ask which security decisions are repetitive, deterministic, and governed well enough to automate safely, and which decisions still require human expertise. 

Organizations should begin by automating high-volume, repeatable workflows where outcomes can be clearly measured and audited.

As confidence grows, automation can expand into complex workflows, provided organizations maintain visibility, policy guardrails, strong identity controls, and meaningful human oversight for higher-consequence decisions.  

Security leaders must build guardrails that compartmentalize trust, limit permissions through least privilege, maintain visibility into autonomous actions, and preserve meaningful human oversight for consequential decisions.

AI should be viewed as a powerful tool that enables organizations to move faster and create value, but every capability that benefits defenders can also be leveraged by attackers.

Applying enduring security principles alongside appropriate governance is what allows organizations to realize AI’s benefits safely. 

The Fundamentals Will Outlast the Technology Cycle 

Even though the conversation around AI often centers on what’s new, security leaders shouldn’t mistake technological change for a change in fundamentals. Being first to adopt the newest models won’t determine who wins. 

It’s the organizations that build AI on resilient foundations that will rise above the rest. [Text Wrapping Break][Text Wrapping Break]The encouraging news is that the industry is beginning to move in that direction.

Today, more than one-third of organizations describe their vulnerability management approach as mostly or primarily machine-led, and that number is expected to grow significantly over the next 12 to 18 months.

Security leaders recognize that scaling cybersecurity is about building trusted automation capable of operating at machine speed while keeping humans in control of the decisions that matter most.

By designing for resilience, treating identity as the foundation of trust, and applying deliberate guardrails to increasingly autonomous systems, CISOs can prepare their organizations for whatever comes next.

AI will continue to evolve, but first principles provide something far more durable: a security strategy that can withstand changes in technology while enabling the business to innovate with confidence. 

BiographyAlfredo Hickman is Chief Information Security Officer at Kai, where he leads enterprise security, product security, and trust as the company pioneers AI-native cybersecurity.

A cybersecurity executive with nearly two decades of experience spanning the private sector, national security, and military service, Hickman has built and scaled security programs from the ground up at high-growth technology companies, most recently serving as CISO at Obsidian Security. A U.S.

Marine Corps infantry veteran, he is recognized for advancing cloud security, AI-driven security operations, and modern security leadership in an era of machine-speed threats.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you